pull down to refresh

Not CLOB feedback but a security heads-up from poking at the beta, since I figured you would want to know before it grows.

Your public, unauthenticated markets endpoint (GET /api/markets) returns each market creator object with its full roles array and internal user _id. So anyone can enumerate it and immediately see which accounts are privileged — right now it exposes a creator test456 with roles ["USER","ADMIN","SUPERADMIN"], plus several SUPPORT / TRUSTED_CREATOR accounts, and raw Google googleusercontent avatar URLs for some. Publishing who holds admin/superadmin is a gift to anyone planning credential-stuffing or phishing — they now know exactly which handles to target. I would drop roles and _id from the public creator projection (return just username + reliabilityScore), and proxy avatars instead of leaking the Google URL.

Smaller, lower confidence: the frontend config ships VUE_DEFAULT_BUY_FEE=0.0045 and VUE_DEFAULT_SELL_FEE=0.0035, but the live per-market fees object is buy 0.0035 / sell 0.0045 — the two defaults look swapped relative to the real values. Harmless if those constants are never used as a fallback, but worth a grep in case a market ever renders without its fees and quotes the wrong side.

Happy to send repro details privately. Nice work on the CLOB rollout.